Liquid’s 598-BTC Standoff Exposes Crypto’s White-Hat Problem
Blockstream refuses to pay for the remaining bitcoin from the Liquid exploit. The dispute tests what responsible research means, and what users need from recovery.

News analysis
Blockstream is refusing to pay for the return of the bitcoin still withheld after the Liquid Network exploit. The latest dispute concerns roughly 598.5 BTC, following the return of about 3,400 BTC earlier in the week. The company’s September 11 position was reported by The Block and Bitcoin Magazine.
That leaves crypto with an uncomfortable question: does returning most of the money earn someone the right to keep the rest?
Our view is that recovery and responsible research deserve separate judgments. Getting funds back is a good outcome for users. It does not, on its own, turn an attacker’s demand into an agreed security reward. Equally, rejecting that demand does not relieve a network’s operators of responsibility for explaining the failure.
A returned balance is not a bounty agreement
“Blockstream will not pay a ransom for the return of stolen funds,” the company said in its September 11 statement, as reproduced by Bitcoin Magazine. That is the company’s characterization of the demand, not a court finding.
The latest refusal matters because a large return had already made the story look like a partial rescue. The Hacker News reported that 3,400 BTC went back to a Liquid Federation address on September 7. Its account identified the remaining approximately 598.5 BTC as change from that transaction, rather than a separately documented reward payment.
A security reward is more than an amount somebody calls a bounty. Its legitimacy depends on the terms and the conduct around it. As a useful industry comparison, HackerOne’s disclosure standards center on defined program scope, reporting a vulnerability to the security team and allowing time for remediation. Those standards are a benchmark here, not evidence that Liquid participated in a HackerOne program.
The distinction is consent. Discovering a dangerous flaw can be valuable work. Taking control of other people’s assets creates a separate obligation to minimize the harm. A partial return helps with that harm; it does not establish that the remaining balance was agreed compensation.
The bug matters as much as the bargaining
The incident is also a warning about where trust sits in a Bitcoin sidechain. Blockstream’s official notice said roughly 4,000 BTC had been withdrawn through SideSwap’s peg-out authorization key, while saying that neither that key nor other keys had been compromised.
That distinction matters. A valid key is not a guarantee that the software has correctly validated everything the key is authorizing.
The public Elements 23.3.4 release includes a fix to proof-verification caching. The underlying change explains that differently grouped inputs could produce the same cache key, allowing a previous successful verification result to be reused incorrectly. The patch makes field boundaries explicit and adds tests for those cases.

The repair identifies a check that could be bypassed.
In ordinary language, the remembered “this checked out” result needed to belong to exactly the right input. The lesson reaches beyond this incident: protecting signing keys and validating what gets signed are separate security jobs.
This was reported as a Liquid and Elements failure. The sources above do not establish a compromise of Bitcoin’s base-layer consensus. Treating every incident involving bitcoin as a failure of the same system would obscure the mechanism readers need to understand.
The community question is trust, not the color of the hat
In a Turkish-language Bitcointalk discussion of the exploit, a commenter using the handle execijutiere focused on the wider security culture:
“For crypto to regain trust, it needs not just better chains, but a better security culture.”
Translated from Turkish. This comment predates Blockstream’s September 11 refusal. It is one participant’s view, not a measure of community consensus.
That is a more useful demand than simply choosing a side in the negotiation. A better security culture would make three things easier to inspect: what failed, what the repair changes and what users can actually do with their funds.
It would also resist turning an attacker’s self-description into a credential. Journalists should be as careful with a flattering label as they are with a damaging accusation.
Refusing to pay is a position. Making users whole is a result.
There is a serious counterargument to a hard refusal. If a negotiated payment recovers assets that would otherwise remain inaccessible, users may prefer the practical result to a principled standoff. That possibility deserves consideration; it should not be dismissed because the demand is objectionable.
But two decisions remain distinct: whether to negotiate to reduce a loss, and whether to describe the person withholding funds as a responsible researcher. A settlement could be pragmatic without becoming a certificate of good conduct.
Blockstream’s position should face the same scrutiny. Rejecting payment does not itself restore backing or redemption. The user-centered measure of success is what happens to holders, including how any unresolved shortfall is handled.
| Milestone | What the evidence shows | What it does not prove |
|---|---|---|
| Software repair | The public Elements release includes the cache fix. | That every operational or reserve question is resolved. |
| Network activity | The Block reported that transactions resumed on September 10. | That conversion back to BTC is fully available. |
| Redemption | The September 11 report said peg-outs remained disabled. | When full redemption will return or how any gap will be covered. |
Sources: Elements release notes and The Block’s September 11 update. Blockstream’s status page still displays an earlier September 10 snapshot describing block production without transactions. These are differently timed reports, not a live availability check.

Network activity and available withdrawals are different tests.
The next headline should answer the holder’s question
Watch for a documented return of the withheld funds, a clear accounting of BTC backing L-BTC and an explicit update on peg-out availability. Those developments would materially change the recovery assessment.
The argument over who gets to wear a white hat will continue. For a holder, the more consequential question is whether the asset they own can once again be redeemed on the terms they expected.
Updated September 12, 2026: Added two source screenshots, editorial annotations and explanations of the evidence. The original publication date is retained.




